PatchSiren cyber security CVE debrief
CVE-2025-31357 Growatt CVE debrief
CVE-2025-31357 is an unauthenticated information disclosure issue in Growatt cloud applications. According to CISA’s CSAF advisory, an attacker who knows a username can obtain that user’s plant list in Growatt cloud portal versions up to 3.6.0. The issue is scored CVSS 3.1 5.3 (Medium) and is limited to confidentiality impact in the supplied vector. CISA’s advisory says the cloud-based vulnerabilities were patched and that no user action is needed for the fix, while also recommending standard account-hardening and security-hygiene steps.
- Vendor
- Growatt
- Product
- Cloud portal
- CVSS
- MEDIUM 5.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-04-15
- Original CVE updated
- 2025-05-06
- Advisory published
- 2025-04-15
- Advisory updated
- 2025-05-06
Who should care
Organizations and individuals using Growatt cloud portal, especially administrators and installers managing customer plants, should care. Because the issue is unauthenticated and username-based, teams should treat any exposed Growatt cloud account data as potentially retrievable by a remote party.
Technical summary
The supplied advisory describes a remote, unauthenticated disclosure condition in Growatt cloud portal (affected version range: <= 3.6.0). Knowing a valid username is sufficient to retrieve a user’s plant list. The published CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) indicates network reachability with no privileges required, no user interaction, and confidentiality impact only.
Defensive priority
Medium. The issue is easy to reach remotely and requires no authentication, but the documented impact is limited to confidentiality and the vendor states the cloud-side fix has been applied. Prioritize review if you operate Growatt cloud portal accounts or have sensitive operational plant data exposed through the service.
Recommended defensive actions
- Confirm whether any organization accounts use Growatt cloud portal versions at or below 3.6.0 and verify the vendor-applied fix is present.
- Review account and plant-list access patterns for unexpected lookups or abnormal usage tied to known usernames.
- Use strong passwords and enable multi-factor authentication where applicable, consistent with Growatt’s guidance.
- Continue to monitor user and installer accounts for unusual activity and report concerns to Growatt [email protected].
- Apply general ICS security best practices and defense-in-depth measures from CISA resources when managing connected cloud services.
Evidence notes
This debrief is based on the supplied CISA CSAF advisory for ICSA-25-105-04 and the CVE record metadata provided in the source corpus. The advisory explicitly states: “An unauthenticated attacker can obtain a user's plant list by knowing the username.” The affected product entry is “Growatt cloud portal: <=3.6.0.” The revision history shows an initial publication on 2025-04-15 and a later revision on 2025-05-06 for typo fixes. No KEV listing was provided in the corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-31357 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-31357
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-31357 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-31357
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-105-04.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-105-04
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.